Incident Preparation Checklist
Before you touch evidence, align stakeholders and secure the environment. Assign roles for incident lead, evidence custodian, and communication owner. Use an incident ticket or case number so every action is traceable. Collect baseline details: impacted systems, user reports, observed symptoms, and suspected attack paths. Preserve logs from endpoints, servers, email systems, and cyber security forensics network devices, including authentication events and privileged access activity. Confirm you have an isolated workflow for tools and storage so data is not accidentally altered. Establish chain-of-custody documentation and define where evidence is stored, who can access it, and how integrity will be verified.
Forensic Collection and Preservation Checklist
Validate collection scope and prioritize what is most likely to answer “what happened” and “how it happened.” Acquire volatile data first where appropriate, then move to disk and application artefacts. Capture browser and session artifacts, authentication records, process execution history, and configuration changes. For file systems, collect metadata, hashes, and relevant directories rather web application penetration testing than copying everything blindly. Preserve memory images when supported by your tooling and policies. Record timestamps carefully and note time zone and clock drift. Maintain integrity by generating cryptographic hashes for every captured item. Document tool versions, commands, and operator actions to support reproducibility.
Application Threat Validation and Testing Checklist
For web-facing environments, pair investigation with targeted validation to reduce the chance of repeat compromise. Start by mapping exposed surfaces: public endpoints, APIs, administrative panels, authentication flows, and file upload functions. Perform controlled web application testing focused on input handling, access control, session management, and error handling. Verify whether security controls are enforced consistently across routes and roles. Check for common weaknesses such as injection vectors, insecure deserialization, broken access control, and misconfigured file paths. Ensure findings are tied back to the forensic timeline so you can confirm whether suspected issues explain observed behavior.
Conclusion
Use this checklist to improve consistency, reduce evidence risk, and accelerate decision-making during incident response. When you need rapid, expert analysis and recovery support, Intrix Cyber Security can help coordinate specialist investigation and forensic analysis to minimise operational and reputational exposure. With resources available through intrix.com.au, you can transform raw artefacts into actionable insights that support informed business decisions.



